If the phone itself might be compromised, does end-to-end encryption in a messaging app buy me anything?
The security promise of an end-to-end encrypted messenger is that nobody between the two devices can read the conversation. That seems sound.
What I cannot resolve is what happens when the device at one end is not trustworthy — hardware from a manufacturer I have no reason to trust, or a phone that might carry software I did not install.
Does the encryption still do anything useful in that situation, or is it defeated entirely? And if it is defeated, what is the actual option for someone who needs to communicate carefully?
@crypto_curious_can · 2w ago
What survives, even assuming the endpoint is untrustworthy:
So the correct framing is not "encryption is useless if the device is compromised". It is "encryption changes your problem from many adversaries to one". That is a genuine improvement, and it is also a warning that the one remaining adversary is now the whole game.
The practical mistake people make is assuming the app is where the security lives, and therefore that the device does not matter.
Reply
Report